VDB

RHSA-2022%3A0450

RHSA-2022%3A0450 PUBLISHED CVSS 7.5 HIGH

A flaw was found in the Java logging library Apache Log4j in version 1.x. JMSAppender in Log4j 1.x is vulnerable to deserialization of untrusted data. This allows a remote attacker to execute code on the server if the deployed application is configured to use JMSAppender and to the attacker's JNDI LDAP endpoint.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatrh-sso-7/sso7-rhel8-operator-bundle@sha256:ad87192dfe806d6ca2a156c0bdf475d82dbe9dad55e626c3e727c02d805e6463_amd64 as a component of Middleware Containers for OpenShiftrh-sso-7/sso7-rhel8-operator-bundle@sha256:ad87192dfe806d6ca2a156c0bdf475d82dbe9dad55e626c3e727c02d805e6463_amd64, *
Red Hatrh-sso-7/sso75-openshift-rhel8@sha256:9ef70013c5f640926f9a3a79db258b2b0f00766d1234d3dd8ba7b415bade986a_amd64 as a component of Middleware Containers for OpenShiftrh-sso-7/sso75-openshift-rhel8@sha256:9ef70013c5f640926f9a3a79db258b2b0f00766d1234d3dd8ba7b415bade986a_amd64, *

Timeline

  • Feb 7, 2022 CVE Published
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 14, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›